CS0-003 · Question #302
The Chief Information Security Officer for an organization recently received approval to install a new EDR solution. Following the installation, the number of alerts that require remediation by an ana
The correct answer is A. SOAR B. SIEM. EDR Alert Overload: Centralizing Security Workload SOAR (A) and SIEM (B) are the correct answers because they directly address the challenge of centralizing and managing a high volume of security alerts. A SIEM aggregates and correlates log/alert data from multiple sources (inclu
Question
The Chief Information Security Officer for an organization recently received approval to install a new EDR solution. Following the installation, the number of alerts that require remediation by an analyst has tripled. Which of the following should the organization utilize to best centralize the workload for the internal security team? (Choose two.)
Options
- ASOAR
- BSIEM
- CMSP
- DNGFW
- EXDR
- FDLP
How the community answered
(31 responses)- A77% (24)
- C3% (1)
- D13% (4)
- F6% (2)
Explanation
EDR Alert Overload: Centralizing Security Workload
SOAR (A) and SIEM (B) are the correct answers because they directly address the challenge of centralizing and managing a high volume of security alerts. A SIEM aggregates and correlates log/alert data from multiple sources (including the new EDR) into a single dashboard, giving analysts a unified view. A SOAR complements this by automating repetitive response tasks and orchestrating workflows, dramatically reducing the manual effort needed to remediate the tripled alert volume.
Why the distractors are wrong:
- MSP (C) is a Managed Service Provider - an outsourced IT vendor, not a centralization tool
- NGFW (D) is a Next-Generation Firewall - a perimeter security tool, not an alert management solution
- XDR (E) could centralize detection, but it replaces the EDR rather than helping manage its output alongside existing infrastructure
- DLP (F) is Data Loss Prevention - focused on data exfiltration, unrelated to alert centralization
Memory Tip: Think "SIEM sees everything, SOAR sorts everything" - when alert fatigue strikes, you need one tool to collect (SIEM) and one to act automatically (SOAR). If a question mentions overwhelming alerts for an internal team, SIEM + SOAR is almost always the answer.
Topics
Community Discussion
No community discussion yet for this question.